Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 249 threats

prompt-injectionlegal-techdocument-poisoningLLM-judgeindirect-injectionASI01 · Goal HijackingAML.T0051Surface: Human InterfacePropagation: Single Hop

A person reportedly embedded hidden AI instructions inside a legal filing, attempting to manipulate any AI system that later reads and processes the document into ruling or advising in their favor. This is a classic indirect prompt injection attack applied to a real-world professional document workflow rather than a novel technical exploit. Severity is moderate since the report describes a single documented incident without technical detail on payload sophistication or actual impact on a legal outcome.

researchbenchmarklong-contextprompt-injectiondefense-evaluationLLM-securityASI01 · Goal HijackingAML.T0051Surface: ModelPropagation: Single Hop

This is an academic benchmark paper (not an active exploit) demonstrating that existing prompt injection defenses, which perform reasonably in short-context settings, largely fail when injected instructions are embedded in long documents like resumes, code, or emails. The authors show even simple heuristic injection attacks bypass state-of-the-art defenses at high success rates in realistic long-context LLM application scenarios. Severity is moderate because it is a research finding highlighting a systemic weakness rather than a disclosed exploit against a specific product or live system.

langflowbroken-access-controlIDORauthenticated-attackeragent-frameworkflow-disclosureASI06 · Memory PoisoningSurface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an improper authorization flaw that lets any authenticated user execute or read another user's private flows. This is a classic access-control bug in an agent-orchestration framework rather than a novel agentic attack technique, but it can expose proprietary prompts, credentials embedded in flows, and business logic, or allow unauthorized execution of another tenant's automation.

langflowssrfagent-frameworkauthenticated-attackernetwork-enumerationASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a server-side request forgery (SSRF) vulnerability that allows an authenticated attacker to make the server send unauthorized requests to internal or external systems. This could be used for internal network reconnaissance or as a stepping stone for further attacks, but requires authentication and has moderate severity per its CVSS score of 4.3.

coding-agentsvulnerability-disclosureopen-sourceocamlrclonecve-backlogai-assisted-exploitationembargoSurface: Supply ChainPropagation: None

This report describes how AI coding agents are now able to turn a mere rumor of a bug (e.g. a patch shared for discussion) into a working exploit within minutes, drastically outpacing traditional open-source security disclosure and embargo timelines. This is not an attack on AI agents themselves, but a broader supply-chain/process risk: maintainers like rclone report a 20x increase in security disclosures alongside overwhelmed CVE assignment pipelines. Severity is assessed as medium because it describes a systemic process/workflow risk rather than a specific exploitable vulnerability in an agent framework or protocol.

DNS-rebindingMCPloopback-bypasslocalhost-serverCSRF-likedropbox-credential-thefttransport-securityASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

The Dash MCP server bound its network listener to loopback but failed to validate the Host header of incoming requests, allowing DNS rebinding attacks from a malicious webpage to reach the local server. An attacker-controlled page in a victim's browser could rebind a domain to 127.0.0.1 and invoke the server's tools using the victim's stored Dropbox credentials. The issue is limited to the network transport mode and was fixed by adding host-checking transport security.

DNS-rebindingMCPlocalhost-exposureCSRFSSRF-adjacentslack-integrationtiger-slackASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

tiger-slack's MCP HTTP transport failed to enable the SDK's built-in host allow-list/DNS-rebinding protection, allowing a malicious webpage visited by a user on the same machine to rebind a DNS name to the local MCP server's address and issue requests to it. This lets an attacker's browser-based script drive the locally running Slack MCP server on behalf of the victim, potentially reading or sending Slack data without authorization. The fix requires explicitly enabling the allow-list option, not just updating the dependency.

mcp-godns-rebindingssrfhost-headerlocalhost-bypasscorsstreamable-httpssecve-2026-81092ASI07 · Inter-Agent CommsAML.T0025AML.T0053Surface: ProtocolPropagation: Single Hop

mcp-go's HTTP transports failed to validate the Host header on loopback-bound requests, allowing a malicious webpage in a user's browser to use DNS rebinding to reach a local MCP server and invoke its tools or read its resources. This breaks the security assumption that only trusted local software can talk to a loopback-bound MCP server. The issue is fixed in 0.56.0 via strict host validation.

hatchetmulti-tenancygRPCbroken-object-level-authorizationworker-hijackagent-orchestrationdenial-of-servicecross-tenantASI08 · Cascading FailuresSurface: Inter Agent CommsPropagation: None

Hatchet, a platform used to orchestrate AI agents and background workflows, contains a missing tenant-ownership check in its Dispatcher gRPC service. An authenticated attacker who can guess or enumerate another tenant's worker UUID can tamper with that worker's labels or forcibly disconnect it, causing integrity and availability impact on shared/multi-tenant deployments. Single-tenant deployments are not meaningfully affected.

data-breachaviationcustomer-datawifiPII

Manchester Airports Group (MAG) disclosed a breach in which attackers accessed and stole customer data, including Wi-Fi sign-up information from Manchester, Stansted, and East Midlands airports. The incident highlights ongoing risks to critical transportation infrastructure operators handling large volumes of traveler personal data.

ICSOTCNCdenial-of-serviceCWE-1285Mitsubishi Electriccritical-manufacturingfirmware-vulnerability

A vulnerability (CVE-2025-2399) in multiple Mitsubishi Electric CNC Series products allows a remote attacker to trigger an out-of-bounds read by sending specially crafted packets to TCP port 683, resulting in a denial-of-service condition. The flaw affects a wide range of M800/M80/E80, M800V/M80V, and M700V/M70V/E70 series controllers used in industrial manufacturing environments. Vendor fixes are available for most affected product lines, with mitigations recommended for systems that cannot be immediately patched.

icsotrockwell-automationpassword-hashingbcryptcwe-916cisa-advisorycritical-manufacturingtransportation

Rockwell Automation OTTO Fleet Manager versions up to V2.36.2 use a bcrypt implementation with an insufficient work factor, weakening stored password hashes against offline brute-force attacks. Exploitation requires an attacker to first obtain an unencrypted system backup, after which weakly hashed credentials could be cracked more easily. Rockwell has released version 2.36.3 to remediate the issue, along with guidance to enable encrypted system backups.

vulnerability-managementsecure-by-designCISAKEVpatch-managementrisk-prioritizationadvisory

CISA released a review analyzing FY2024-2025 vulnerability and exploitation data, finding that most breaches stem from unpatched, well-known vulnerabilities rather than novel attack techniques. The report highlights recurring software weakness classes and provides a risk-based prioritization framework (per BOD 26-04) to help organizations focus remediation efforts before automated and AI-assisted vulnerability discovery becomes more prevalent.

linuxprivilege-escalationrace-conditionred-hatcisa-kevlocal-exploit

CVE-2015-3246 is a race condition vulnerability in Red Hat's libuser library that allows authenticated local users to corrupt /etc/passwd, resulting in denial of service or privilege escalation. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild despite its age. Organizations still running affected libuser versions on Linux systems should prioritize patching before the specified due date.

WebMCPbrowser-agentsame-origin-policytool-provenanceprompt-injectionresearchdefense-proposalquarantine-agentcapability-credentialsASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

This is a defensive research paper, not an active exploit: it identifies real trust-boundary gaps in the emerging W3C WebMCP proposal that let malicious web pages spoof tool ownership, manipulate tool lifecycles, and inject prompts via tool metadata/descriptions into browser-integrated LLM agents. The authors propose and empirically validate a dual-layer runtime (cryptographic tool provenance plus a quarantine/privileged agent split) that reduces these attack classes to near-zero success, while also disclosing a residual bypass via malicious tool names invoked before inspection.

iransanctionscritical-infrastructurestate-sponsoredtreasurygeopolitical

The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors linked to breaches of critical infrastructure, as part of a broader economic pressure campaign against Iran. This is a policy and enforcement action rather than a newly disclosed technical vulnerability, though it signals continued Iranian state-sponsored targeting of critical infrastructure sectors.

npmphishingsupply-chainfake-captchacloudflare-impersonationagent-relevant

Threat actors are abusing npm and its mirror services to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens. Visitors who interact with these fake pages are redirected to attacker-controlled sites, likely for further phishing, malware delivery, or credential theft. The abuse leverages the inherent trust and reachability of npm's infrastructure to evade detection and blocklisting.

data-breachPIISSN-exposuremedical-datamuseum-sectorthird-party-risk

The Los Angeles County Museum of Art (LACMA) disclosed a data breach from the prior year that exposed sensitive personal information, including Social Security numbers and medical data, belonging to customers and employees. Details on the initial attack vector and threat actor attribution have not been publicly confirmed at this time.

MCPPHPSSEdenial-of-servicehttp-transportunbounded-buffersupply-chainASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

The official MCP PHP SDK contains a flaw where its HTTP transport buffers Server-Sent Events data without any size limit, waiting indefinitely for a delimiter that a malicious server can simply withhold. A hostile or compromised MCP server (or a man-in-the-middle) can exploit this to crash or hang any connecting PHP-based MCP client through memory exhaustion, with no authentication or user interaction required.

weekly-recapsupply-chaincredential-leakplc-securitygitlabstripeexposed-servicesagent-relevant

This is a weekly aggregated security recap covering multiple loosely-related incidents, including AI-assisted attacks against industrial PLC systems, GitLab-related compromises, and leaked Stripe API keys. The report is high-level and lacks technical depth on specific CVEs, exploit chains, or IOCs, functioning primarily as an industry news digest rather than a single actionable threat profile.